npm audit signatures on @sume-com/sdk 0.2.0: what it proves, what not
Run npm audit signatures on @sume-com/sdk 0.2.0 before deploy. It checks the registry signature; the registry lists no provenance attestation for this version.

Run npm audit signatures after installing @sume-com/sdk@0.2.0: it verifies the registry signature of the tarball you installed, and in our run it reported no invalid and no missing signatures. It does not prove that the package was built from a particular commit. The npm registry metadata for 0.2.0 that we read lists a signature but no provenance attestation, so a clean result means the registry vouches for the bytes, not that a build log does. That is still useful: it catches a tampered mirror or a corrupted cache, which is the common failure in a CI pipeline.
This is worth doing now because Node.js 26.11.0, released October 7, bundles npm 11.20.0 according to its release notes, and many teams will refresh their toolchains and lockfiles as Node 26 moves to LTS. The commands below were run with npm 10.9.2 on a fresh project; we did not run them on npm 11.20.
What each check tells you
The SDK is small by design: the SDK docs and the package metadata agree that it is MIT licensed and has no runtime dependencies. That keeps the audit surface to one package, which makes the signature step cheap. The table lists what we saw and what it implies.
| Check | Result in our run | What it means |
|---|---|---|
| License | MIT | Matches the SDK docs |
| Runtime dependencies | None listed | One package to audit |
| Registry signatures | Present on 0.2.0 | npm audit signatures can verify them |
| npm audit signatures | No invalid, no missing | Tarball matches the signed registry record |
| Provenance attestation on 0.2.0 | None in registry metadata | No build-to-source link to check |
Steps
- Pin the version exactly with
--save-exact. In a0.xrange a caret allows only patch updates, so a new minor needs an explicit edit. - Run
npm audit signaturesin CI afternpm ci, and fail the job on any invalid or missing result. - Record the
dist.integrityvalue fromnpm viewnext to the version in your change log so a later reinstall can be compared. - Keep the audit in the same job that builds the container image, so the artifact you ship is the artifact you checked, not a later reinstall.
- Review the lockfile diff whenever the SDK version changes; the signature check does not tell you what changed.
Commands
The last line reads the registry record directly and prints how many signatures and attestations it lists.
npm install --save-exact @sume-com/sdk@0.2.0
npm audit signatures
npm view @sume-com/sdk@0.2.0 license dependencies dist.integrity
curl -s "https://registry.npmjs.org/@sume-com%2fsdk/0.2.0" | node -e 'let s="";process.stdin.on("data",d=>s+=d).on("end",()=>{const d=JSON.parse(s).dist;console.log("signatures:",d.signatures.length,"attestations:",d.attestations??"none")})'What Sume does not do
Sume does not claim a supply-chain attestation for 0.2.0 on this page, and the check above does not replace reading the code or pinning your dependencies. Because the generated functions and helpers in the SDK are plain TypeScript compiled to ESM, you can also read the published dist folder after install if your policy needs a manual review.
Sources
Related posts
More in Developers
- Omni Flash API errors: which to retry and which to fix
A retry policy for Gemini Omni Flash 1.1 calls on Sume: 400, 401, 402, 409, 429 rate_limited, 429 queue_full and 503 each mapped to retry, wait or fix.
- Omni job status names: pending vs queued, cancelled vs canceled
Sume's /v1/videos poll uses pending, in_progress, completed, failed and cancelled; /v1/jobs uses queued, processing and canceled. Mapping table for Omni code.
- Omni Flash on /v1/videos vs /v1/video-router: the field map
The same Gemini Omni Flash 1.1 runs on /v1/videos and /v1/video-router/generate with different fields. Field map for frame_images, input_references, video_url.
- Omni resolution values: 4K, lowercase 4k, and what is rejected
Gemini Omni Flash 1.1 on Sume takes 360p, 720p, 1080p and 4K. The catalog also accepts lowercase 4k as an alias. Which strings fail, and the price of each.
Written by Sume